Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:13-09-2015 02
Ran by SYSTEM on MININT-5K93512 (13-09-2015 21:16:24)
Running from F:\
Platform: Windows 7 Home Premium (X86) Language: English (United States)
Internet Explorer Version 9
Boot Mode: Recovery
Default: ControlSet001
ATTENTION!:=====> If the system is bootable FRST must be run from normal or Safe mode to create a complete log.
Tutorial for Farbar Recovery Scan Tool:
FRST Tutorial - How to use Farbar Recovery Scan Tool - Geeks to Go Forum
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [] => [X]
HKLM\...\Run: [AVG_UI] => C:\Program Files\AVG\AVG2015\avgui.exe [3730344 2015-07-07] (AVG Technologies CZ, s.r.o.)
HKLM\...\RunOnce: [*Restore] => C:\Windows\system32\rstrui.exe [262656 2010-11-20] (Microsoft Corporation)
HKLM\...\Policies\Explorer: [TaskbarNoNotification] 0
HKLM\...\Policies\Explorer: [HideSCAHealth] 0
AppInit_DLLs: C:\PROGRA~1\GOOGLE\GOOGLE~1\GO36F4~1.DLL => C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll [123392 2010-08-23] (Google)
==================== Services (Whitelisted) ========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S2 AVGIDSAgent; C:\Program Files\AVG\AVG2015\avgidsagent.exe [3518376 2015-07-07] (AVG Technologies CZ, s.r.o.)
S2 avgwd; C:\Program Files\AVG\AVG2015\avgwdsvc.exe [314304 2015-07-07] (AVG Technologies CZ, s.r.o.)
S4 CLHNService; C:\Program Files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe [75048 2008-12-18] ()
S4 ePowerSvc; C:\Program Files\Acer\Acer PowerSmart Manager\ePowerSvc.exe [690720 2009-08-26] (Acer Incorporated)
S4 EpsonBidirectionalService; C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe [94208 2006-12-19] (SEIKO EPSON CORPORATION)
S4 EPSON_EB_RPCV4_01; C:\ProgramData\EPSON\EPW!3 SSRP\E_S40ST7.EXE [143872 2007-12-16] (SEIKO EPSON CORPORATION)
S4 EPSON_PM_RPCV4_01; C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RP7.EXE [113664 2007-01-10] (SEIKO EPSON CORPORATION)
S4 GoogleDesktopManager-051210-111108; C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [30192 2010-08-23] (Google)
S4 McComponentHostService; C:\Program Files\McAfee Security Scan\3.11.163\McCHSvc.exe [235696 2015-07-31] (McAfee, Inc.)
S2 MWLService; C:\Program Files\EgisTec\MyWinLocker 3\x86\\MWLService.exe [306736 2008-10-27] (EgisTec Inc.)
S4 NTI IScheduleSvc; C:\Program Files\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe [61184 2009-04-11] (NewTech Infosystems, Inc.)
S4 NTISchedulerSvc; C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe [144632 2008-09-23] (NewTech Infosystems, Inc.)
S2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-26] (Microsoft Corporation)
S2 gupdate; "C:\Program Files\Google\Update\GoogleUpdate.exe" /svc [X]
S3 gupdatem; "C:\Program Files\Google\Update\GoogleUpdate.exe" /medsvc [X]
===================== Drivers (Whitelisted) ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 athr; C:\Windows\System32\DRIVERS\athr.sys [3208496 2015-05-19] (Qualcomm Atheros Communications, Inc.)
S1 Avgdiskx; C:\Windows\System32\DRIVERS\avgdiskx.sys [132576 2015-03-11] (AVG Technologies CZ, s.r.o.)
S1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdriverx.sys [231856 2015-06-26] (AVG Technologies CZ, s.r.o.)
S0 AVGIDSHX; C:\Windows\System32\DRIVERS\avgidshx.sys [190944 2015-05-12] (AVG Technologies CZ, s.r.o.)
S1 AVGIDSShim; C:\Windows\System32\DRIVERS\avgidsshimx.sys [29664 2015-05-14] (AVG Technologies CZ, s.r.o.)
S1 Avgldx86; C:\Windows\System32\DRIVERS\avgldx86.sys [207328 2015-06-16] (AVG Technologies CZ, s.r.o.)
S0 Avglogx; C:\Windows\System32\DRIVERS\avglogx.sys [290272 2015-05-07] (AVG Technologies CZ, s.r.o.)
S0 Avgmfx86; C:\Windows\System32\DRIVERS\avgmfx86.sys [170464 2015-06-10] (AVG Technologies CZ, s.r.o.)
S0 Avgrkx86; C:\Windows\System32\DRIVERS\avgrkx86.sys [35808 2015-03-20] (AVG Technologies CZ, s.r.o.)
S1 Avgtdix; C:\Windows\System32\DRIVERS\avgtdix.sys [213984 2015-05-12] (AVG Technologies CZ, s.r.o.)
S3 cpudrv; C:\Program Files\SystemRequirementsLab\cpudrv.sys [11336 2011-06-02] ()
S3 hwusbfake; C:\Windows\System32\DRIVERS\ewusbfake.sys [103040 2008-12-30] (Huawei Technologies Co., Ltd.)
S2 mwlPSDFilter; C:\Windows\System32\DRIVERS\mwlPSDFilter.sys [19504 2008-10-09] (Egis Incorporated.)
S2 mwlPSDNServ; C:\Windows\System32\DRIVERS\mwlPSDNServ.sys [16432 2008-10-09] (Egis Incorporated.)
S2 mwlPSDVDisk; C:\Windows\System32\DRIVERS\mwlPSDVDisk.sys [59952 2008-10-09] (Egis Incorporated.)
S3 IntcAzAudAddService; system32\drivers\RTKVHDA.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-09-13 21:15 - 2015-09-13 21:16 - 00000000 ____D C:\FRST
2015-09-11 11:42 - 2015-09-13 19:48 - 00000000 ____D C:\Users\Jo\Desktop\ - Windows Repair
2015-09-11 11:41 - 2015-09-11 11:41 - 18073209 _____ C:\Users\Jo\Desktop\
2015-09-11 05:15 - 2015-09-11 05:15 - 00000000 ____D C:\63f4e3b070a23d882dcfab1f
2015-09-11 05:12 - 2015-09-11 05:13 - 11840839 _____ C:\Users\Jo\Downloads\Windows6.1-KB2670838-x64.msu
2015-09-11 05:11 - 2015-09-11 05:11 - 00000000 ____D C:\e1897e665ad39a87df3f
2015-09-11 05:10 - 2015-09-11 05:11 - 01003796 _____ C:\Users\Jo\Downloads\Windows6.1-KB2834140-v2-x64.msu
2015-09-11 04:54 - 2015-09-11 04:54 - 00599885 _____ C:\Users\Jo\Downloads\Windows6.1-KB2834140-v2-x86 (4).msu
2015-09-11 04:54 - 2015-09-11 04:54 - 00000000 ____D C:\cab123bc7705fed42cb3a4
2015-09-11 04:53 - 2015-09-11 04:53 - 00000000 ____D C:\27f7f0596b8a37dc6419c001db54df60
2015-09-11 04:52 - 2015-09-11 04:53 - 00599885 _____ C:\Users\Jo\Downloads\Windows6.1-KB2834140-v2-x86 (3).msu
2015-09-11 03:57 - 2015-09-11 03:57 - 00000000 ____D C:\4f6dfb480f70a133c82c3f3aee3753c7
2015-09-11 03:56 - 2015-09-11 03:57 - 05911327 _____ C:\Users\Jo\Downloads\Windows6.1-KB2670838-x86 (8).msu
2015-09-11 03:55 - 2015-09-11 03:56 - 05911327 _____ C:\Users\Jo\Downloads\Windows6.1-KB2670838-x86 (7).msu
2015-09-11 03:45 - 2015-09-11 03:45 - 00000000 ____D C:\b4c2c39bc46ba5f57b01e910b4
2015-09-11 03:44 - 2015-09-11 03:44 - 00230071 _____ C:\Users\Jo\Downloads\Windows6.1-KB2786081-x86 (4).msu
2015-09-11 03:37 - 2015-09-11 03:37 - 00000000 ____D C:\c8ac6b3c35f3693b48
2015-09-11 03:36 - 2015-09-11 03:37 - 05911327 _____ C:\Users\Jo\Downloads\Windows6.1-KB2670838-x86 (6).msu
2015-09-11 03:17 - 2015-09-11 03:17 - 05911327 _____ C:\Users\Jo\Downloads\Windows6.1-KB2670838-x86 (5).msu
2015-09-11 03:17 - 2015-09-11 03:17 - 00000000 ____D C:\82087c94beafe584a17d95
2015-09-11 03:16 - 2015-09-11 03:16 - 01162805 _____ C:\Users\Jo\Downloads\Windows6.1-KB2533623-x86 (6).msu
2015-09-11 03:16 - 2014-05-14 08:23 - 01973728 _____ (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2015-09-11 03:16 - 2014-05-14 08:23 - 00054240 _____ (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2015-09-11 03:16 - 2014-05-14 08:23 - 00045536 _____ (Microsoft Corporation) C:\Windows\System32\wups2.dll
2015-09-11 03:16 - 2014-05-14 08:17 - 02425856 _____ (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2015-09-11 03:15 - 2014-05-14 08:23 - 00581600 _____ (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2015-09-11 03:15 - 2014-05-14 08:23 - 00036320 _____ (Microsoft Corporation) C:\Windows\System32\wups.dll
2015-09-11 03:15 - 2014-05-14 08:17 - 00092672 _____ (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2015-09-11 03:15 - 2014-05-14 00:23 - 00179656 _____ (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2015-09-11 03:15 - 2014-05-14 00:17 - 00033792 _____ (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2015-09-11 03:14 - 2015-09-11 03:14 - 04904874 _____ C:\Users\Jo\Downloads\Windows6.1-KB2731771-x86 (2).msu
2015-09-11 03:11 - 2015-09-11 03:11 - 01662478 _____ C:\Users\Jo\Downloads\Windows6.1-KB2729094-v2-x86 (4).msu
2015-09-10 11:36 - 2015-09-10 11:36 - 00000000 ____D C:\9a12e446902bf52d801b6e
2015-09-10 11:35 - 2015-09-10 11:36 - 01162805 _____ C:\Users\Jo\Downloads\Windows6.1-KB2533623-x86 (5).msu
2015-09-10 11:32 - 2015-09-10 11:32 - 05911327 _____ C:\Users\Jo\Downloads\Windows6.1-KB2670838-x86 (4).msu
2015-09-10 11:31 - 2015-09-10 11:31 - 00230071 _____ C:\Users\Jo\Downloads\Windows6.1-KB2786081-x86 (3).msu
2015-09-10 11:29 - 2015-09-10 11:30 - 00599885 _____ C:\Users\Jo\Downloads\Windows6.1-KB2834140-v2-x86 (2).msu
2015-09-10 11:24 - 2015-09-10 11:24 - 01162805 _____ C:\Users\Jo\Downloads\Windows6.1-KB2533623-x86 (4).msu
2015-09-10 11:24 - 2015-09-10 11:24 - 00000000 ____D C:\0d1aa39ddc41b2bac2efbfc55810
2015-09-10 10:59 - 2015-09-10 10:59 - 01162805 _____ C:\Users\Jo\Downloads\Windows6.1-KB2533623-x86 (3).msu
2015-09-10 10:55 - 2015-09-10 10:55 - 05911327 _____ C:\Users\Jo\Downloads\Windows6.1-KB2670838-x86 (3).msu
2015-09-10 10:55 - 2015-09-10 10:55 - 00000000 ____D C:\62e721887ef6174da4634a
2015-09-10 10:47 - 2012-11-22 18:48 - 00049152 _____ (Microsoft Corporation) C:\Windows\System32\taskhost.exe
2015-09-10 10:40 - 2015-09-10 10:41 - 00230071 _____ C:\Users\Jo\Downloads\Windows6.1-KB2786081-x86 (2).msu
2015-09-10 10:37 - 2015-09-10 10:37 - 05911327 _____ C:\Users\Jo\Downloads\Windows6.1-KB2670838-x86 (2).msu
2015-09-10 10:36 - 2015-09-10 10:36 - 01162805 _____ C:\Users\Jo\Downloads\Windows6.1-KB2533623-x86 (2).msu
2015-09-10 10:35 - 2015-09-10 10:35 - 04904874 _____ C:\Users\Jo\Downloads\Windows6.1-KB2731771-x86 (1).msu
2015-09-10 10:34 - 2015-09-10 10:35 - 01662478 _____ C:\Users\Jo\Downloads\Windows6.1-KB2729094-v2-x86 (3).msu
2015-09-10 10:33 - 2015-09-10 10:33 - 01662478 _____ C:\Users\Jo\Downloads\Windows6.1-KB2729094-v2-x86 (2).msu
2015-09-10 10:28 - 2015-09-10 10:29 - 01662478 _____ C:\Users\Jo\Downloads\Windows6.1-KB2729094-v2-x86 (1).msu
2015-09-10 10:25 - 2015-09-10 10:28 - 05911327 _____ C:\Users\Jo\Downloads\Windows6.1-KB2670838-x86 (1).msu
2015-09-10 10:25 - 2015-09-10 10:27 - 01162805 _____ C:\Users\Jo\Downloads\Windows6.1-KB2533623-x86 (1).msu
2015-09-10 10:25 - 2015-09-10 10:27 - 00230071 _____ C:\Users\Jo\Downloads\Windows6.1-KB2786081-x86 (1).msu
2015-09-10 10:25 - 2015-09-10 10:26 - 00599885 _____ C:\Users\Jo\Downloads\Windows6.1-KB2834140-v2-x86 (1).msu
2015-09-10 10:23 - 2015-09-10 10:25 - 00599885 _____ C:\Users\Jo\Downloads\Windows6.1-KB2834140-v2-x86.msu
2015-09-10 10:23 - 2015-09-10 10:25 - 00230071 _____ C:\Users\Jo\Downloads\Windows6.1-KB2786081-x86.msu
2015-09-10 10:23 - 2015-09-10 10:24 - 05911327 _____ C:\Users\Jo\Downloads\Windows6.1-KB2670838-x86.msu
2015-09-10 10:23 - 2015-09-10 10:23 - 04904874 _____ C:\Users\Jo\Downloads\Windows6.1-KB2731771-x86.msu
2015-09-10 10:23 - 2015-09-10 10:23 - 01162805 _____ C:\Users\Jo\Downloads\Windows6.1-KB2533623-x86.msu
2015-09-10 10:23 - 2015-09-10 10:23 - 00000000 ____D C:\554584b4a64aa0a495d40b89761c
2015-09-10 10:22 - 2015-09-10 10:23 - 01662478 _____ C:\Users\Jo\Downloads\Windows6.1-KB2729094-v2-x86.msu
2015-09-10 09:49 - 2015-09-11 04:48 - 00000134 _____ C:\Users\Jo\Desktop\Internet Explorer Troubleshooting.url
2015-09-10 09:41 - 2015-09-11 04:49 - 00025424 _____ C:\Windows\IE11_main.log
2015-09-10 09:41 - 2015-09-10 09:41 - 02077392 _____ (Microsoft Corporation) C:\Users\Jo\Desktop\IE11-Windows6.1.exe
2015-09-10 08:48 - 2015-09-10 08:48 - 00000000 ____D C:\a171b44b27132d4c2c8f
2015-09-10 06:18 - 2015-09-10 06:18 - 00000000 ____D C:\Windows\System32\SPReview
2015-09-10 05:50 - 2015-09-10 05:50 - 00140608 _____ C:\Windows\Minidump\091015-59483-01.dmp
2015-09-10 04:30 - 2015-09-10 14:34 - 00000000 ____D C:\80d2b125541bd69c2e
2015-09-08 11:18 - 2015-09-08 11:18 - 00002950 _____ C:\Users\Jo\Desktop\SFCScript.txt
2015-09-07 10:05 - 2015-09-09 11:37 - 15713417 _____ C:\Users\Jo\Desktop\
2015-09-06 08:32 - 2015-09-06 08:32 - 00000000 ____D C:\Windows\pss
2015-09-06 08:26 - 2015-09-08 11:19 - 00000000 ____D C:\Users\Jo\AppData\Local\niemiro
2015-09-05 10:21 - 2015-09-05 10:21 - 03764224 _____ C:\Users\Jo\Desktop\SxS
2015-09-05 10:20 - 2015-09-05 10:20 - 04882432 _____ C:\Users\Jo\Desktop\CBS
2015-09-05 09:12 - 2015-09-08 11:19 - 00021406 _____ C:\Users\Jo\Desktop\SFCFix.txt
2015-09-05 09:10 - 2015-09-05 09:10 - 01319424 _____ (niemiro) C:\Users\Jo\Desktop\SFCFix.exe
2015-09-05 01:43 - 2015-09-05 01:44 - 00000000 ____D C:\Program Files\McAfee Security Scan
2015-08-31 07:15 - 2015-08-31 07:16 - 00000000 ____D C:\Users\Jo\Downloads\Katy Perry - PRISM (Deluxe Version)
2015-08-16 05:51 - 2015-09-10 08:27 - 00001120 _____ C:\Windows\PFRO.log
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-09-13 19:48 - 2010-02-05 10:14 - 00000000 ____D C:\users\Jo
2015-09-13 19:48 - 2009-07-13 18:37 - 00000000 ____D C:\Windows\System32\wfp
2015-09-13 19:48 - 2009-07-13 18:37 - 00000000 ____D C:\Windows\registration
2015-09-11 11:26 - 2009-07-13 18:37 - 00000000 ____D C:\Windows\tracing
2015-09-11 07:56 - 2009-02-11 12:16 - 00000000 ___HD C:\Program Files\InstallShield Installation Information
2015-09-11 07:49 - 2010-02-05 10:13 - 00019344 ____H C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-09-11 07:49 - 2010-02-05 10:13 - 00019344 ____H C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-09-11 07:46 - 2010-02-05 10:42 - 01611984 _____ C:\Windows\WindowsUpdate.log
2015-09-11 07:41 - 2010-07-09 09:59 - 00065536 _____ C:\Windows\System32\Ikeext.etl
2015-09-11 07:40 - 2015-08-05 10:45 - 00376460 _____ C:\Windows\setupact.log
2015-09-11 04:35 - 2010-02-05 10:50 - 00734802 _____ C:\Windows\System32\PerfStringBackup.INI
2015-09-11 03:34 - 2009-07-13 18:37 - 00000000 ____D C:\Windows\Microsoft.NET
2015-09-11 03:10 - 2015-07-16 10:50 - 00000000 ____D C:\ProgramData\MFAData
2015-09-10 14:34 - 2009-07-13 18:37 - 00000000 ____D C:\Windows\TAPI
2015-09-10 14:34 - 2009-07-13 18:37 - 00000000 ____D C:\Windows\System32\spp
2015-09-10 14:34 - 2009-07-13 18:37 - 00000000 ____D C:\Windows\System32\Speech
2015-09-10 14:34 - 2009-07-13 18:37 - 00000000 ____D C:\Windows\System32\MUI
2015-09-10 14:34 - 2009-07-13 18:37 - 00000000 ____D C:\Windows\security
2015-09-10 08:48 - 2013-12-08 04:11 - 00000000 ____D C:\Windows\System32\MRT
2015-09-10 08:40 - 2009-07-13 20:33 - 00427616 _____ C:\Windows\System32\FNTCACHE.DAT
2015-09-10 06:42 - 2009-07-13 23:49 - 00000000 ____D C:\Program Files\Windows Journal
2015-09-10 06:42 - 2009-07-13 20:52 - 00000000 ____D C:\Program Files\Windows Sidebar
2015-09-10 06:42 - 2009-07-13 20:52 - 00000000 ____D C:\Program Files\Windows Portable Devices
2015-09-10 06:42 - 2009-07-13 20:52 - 00000000 ____D C:\Program Files\Windows Photo Viewer
2015-09-10 06:42 - 2009-07-13 20:52 - 00000000 ____D C:\Program Files\Windows Defender
2015-09-10 06:42 - 2009-07-13 20:52 - 00000000 ____D C:\Program Files\DVD Maker
2015-09-10 06:42 - 2009-07-13 18:37 - 00000000 ____D C:\Program Files\Common Files\System
2015-09-10 06:41 - 2009-07-13 18:37 - 00000000 ____D C:\Windows\System32\AdvancedInstallers
2015-09-10 05:50 - 2010-02-05 13:01 - 00000000 ____D C:\Windows\Minidump
2015-09-10 02:54 - 2009-02-18 04:10 - 00000000 ____D C:\ProgramData\Microsoft Help
2015-09-09 11:40 - 2013-11-28 01:30 - 00000000 ____D C:\Users\Jo\AppData\Local\991821C2-F158-451E-B28B-29631A0045B2.aplzod
2015-09-09 09:57 - 2009-10-02 23:01 - 00000000 ____D C:\Users\Jo\AppData\Local\Google
2015-09-08 11:19 - 2015-07-22 12:43 - 00000000 ____D C:\SFCFix
2015-09-06 08:17 - 2012-12-28 05:40 - 00000000 ___RD C:\Users\Jo\Dropbox
2015-09-06 08:17 - 2012-12-28 05:33 - 00000000 ____D C:\Users\Jo\AppData\Roaming\Dropbox
2015-09-05 08:53 - 2013-12-08 04:16 - 00000000 ____D C:\Users\Jo\AppData\Local\Windows Live
2015-08-31 09:17 - 2010-02-24 10:55 - 00000000 ____D C:\Users\Jo\AppData\Roaming\uTorrent
2015-08-26 09:36 - 2013-12-08 04:11 - 132039072 _____ (Microsoft Corporation) C:\Windows\System32\MRT.exe
2015-08-18 00:59 - 2010-02-24 11:55 - 00000000 ____D C:\Users\Jo\AppData\Roaming\Apple Computer
2015-08-16 13:24 - 2009-11-09 14:35 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2015-08-16 06:52 - 2015-07-10 08:45 - 00000000 ___SD C:\Windows\System32\CompatTel
2015-08-16 06:52 - 2015-07-10 08:45 - 00000000 ____D C:\Windows\System32\appraiser
2015-08-16 06:20 - 2012-09-09 02:45 - 00778440 _____ (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerApp.exe
2015-08-16 06:20 - 2012-09-09 02:45 - 00142536 _____ (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerCPLApp.cpl
2015-08-16 05:54 - 2015-05-01 09:41 - 00000000 ____D C:\Users\Jo\AppData\Roaming\Update Manager
Files to move or delete:
Some files in TEMP:
==================== Known DLLs (Whitelisted) =========================
==================== Bamital & volsnap =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\dnsapi.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
safeboot: {a9d4d022-d441-11dc-8a35-e9a1536067d6} => The system is configured to boot to Safe Mode <===== ATTENTION
==================== Restore Points =========================
Restore point date: 2015-09-10 11:19:42
Restore point date: 2015-09-10 11:33:47
Restore point date: 2015-09-11 03:14:52
Restore point date: 2015-09-11 03:51:35
Restore point date: 2015-09-11 03:53:14
Restore point date: 2015-09-11 07:55:41
Restore point date: 2015-09-11 08:02:42
==================== BCD ================================
Windows Boot Manager
identifier {bootmgr}
device partition=C:
description Windows Boot Manager
locale en-US
inherit {globalsettings}
default {default}
resumeobject {a9d4d023-d441-11dc-8a35-e9a1536067d6}
displayorder {default}
toolsdisplayorder {memdiag}
timeout 30
Windows Boot Loader
identifier {572bcd56-ffa7-11d9-aae0-0007e994107d}
device ramdisk=[D:]\x86\winre.wim,{ad6c7bc8-fa0f-11da-8ddf-0013200354d8}
path \windows\system32\boot\winload.exe
description Windows Recovery Environment
osdevice ramdisk=[D:]\x86\winre.wim,{ad6c7bc8-fa0f-11da-8ddf-0013200354d8}
systemroot \windows
nx OptIn
detecthal Yes
winpe Yes
Windows Boot Loader
identifier {default}
device partition=C:
path \Windows\system32\winload.exe
description Windows 7
locale en-US
inherit {bootloadersettings}
recoverysequence {current}
recoveryenabled Yes
osdevice partition=C:
systemroot \Windows
resumeobject {a9d4d023-d441-11dc-8a35-e9a1536067d6}
nx OptIn
safeboot Network
Windows Boot Loader
identifier {current}
device ramdisk=[C:]\Recovery\de568600-1286-11df-83d5-001f16ae5b4f\Winre.wim,{de568601-1286-11df-83d5-001f16ae5b4f}
path \windows\system32\winload.exe
description Windows Recovery Environment
inherit {bootloadersettings}
osdevice ramdisk=[C:]\Recovery\de568600-1286-11df-83d5-001f16ae5b4f\Winre.wim,{de568601-1286-11df-83d5-001f16ae5b4f}
systemroot \windows
nx OptIn
winpe Yes
Resume from Hibernate
identifier {a9d4d023-d441-11dc-8a35-e9a1536067d6}
device partition=C:
path \Windows\system32\winresume.exe
description Windows Resume Application
locale en-US
inherit {resumeloadersettings}
filedevice partition=C:
filepath \hiberfil.sys
pae Yes
debugoptionenabled No
Windows Memory Tester
identifier {memdiag}
device partition=C:
path \boot\memtest.exe
description Windows Memory Diagnostic
locale en-US
inherit {globalsettings}
badmemoryaccess Yes
Windows Legacy OS Loader
identifier {ntldr}
device unknown
path \ntldr
description Earlier Version of Windows
EMS Settings
identifier {emssettings}
bootems Yes
Debugger Settings
identifier {dbgsettings}
debugtype Serial
debugport 1
baudrate 115200
RAM Defects
identifier {badmemory}
Global Settings
identifier {globalsettings}
inherit {dbgsettings}
Boot Loader Settings
identifier {bootloadersettings}
inherit {globalsettings}
Hypervisor Settings
identifier {hypervisorsettings}
hypervisordebugtype Serial
hypervisordebugport 1
hypervisorbaudrate 115200
Resume Loader Settings
identifier {resumeloadersettings}
inherit {globalsettings}
Device options
identifier {ad6c7bc8-fa0f-11da-8ddf-0013200354d8}
description Ramdisk Device Options
ramdisksdidevice partition=D:
ramdisksdipath \X86\boot.sdi
Device options
identifier {de568601-1286-11df-83d5-001f16ae5b4f}
description Ramdisk Options
ramdisksdidevice partition=C:
ramdisksdipath \Recovery\de568600-1286-11df-83d5-001f16ae5b4f\boot.sdi
==================== Memory info ===========================
Percentage of memory in use: 15%
Total physical RAM: 3000.83 MB
Available physical RAM: 2537.58 MB
Total Virtual: 2999.11 MB
Available Virtual: 2542.11 MB
==================== Drives ================================
Drive c: (ACER) (Fixed) (Total:139.28 GB) (Free:13.76 GB) NTFS ==>[drive with boot components (obtained from BCD)]
Drive d: (PQSERVICE) (Fixed) (Total:9.76 GB) (Free:1.96 GB) FAT32
Drive f: (Volume) (Fixed) (Total:74.53 GB) (Free:57.46 GB) NTFS
Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
==================== MBR & Partition Table ==================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 149.1 GB) (Disk ID: 91FBBAA4)
Partition 1: (Not Active) - (Size=9.8 GB) - (Type=27)
Partition 2: (Active) - (Size=139.3 GB) - (Type=07 NTFS)
Disk: 1 (MBR Code: Windows 7 or 8) (Size: 74.5 GB) (Disk ID: 64195101)
Partition 1: (Not Active) - (Size=74.5 GB) - (Type=07 NTFS)
LastRegBack: 2015-09-08 10:34
==================== End of FRST.txt ============================